What to check on a supplier’s ISO 27001:2022 certificate
A supplier’s ISO 27001 certificate is worth what its scope statement says it is worth. Scope names the part of the organisation an auditor examined, and it can leave the service you are buying outside that boundary altogether.
The edition matters too. Accredited certification to ISO/IEC 27001:2013 has not existed since 31 October 2025, so a certificate showing the old version needs a question before you score the bid. ISO/IEC 27001:2022 is the current standard. Neither check needs a security specialist and both take minutes.
What an ISO 27001 certificate actually tells a buyer
ISO 27001 certifies a management system. An auditor examines how a company runs information security as a business function, from who is granted access to what happens after an incident, and issues a certificate against the requirements of the standard.
Product assurance is a separate question. Nobody inspected the code in your tender or the servers your service will run on, and a supplier can hold live certification while the team delivering your contract sits outside the audited boundary. Treat the certificate as proof that a security function exists and is externally inspected, then ask separately how the service itself is built and hosted.
Is an ISO 27001:2013 certificate still valid?
No. The transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 closed on 31 October 2025. Accredited certification to the 2013 version ended on that date, so a 2013 certificate presented today does not evidence current accredited certification.
UKAS, the UK national accreditation body, set out the timetable in its technical bulletin on transition arrangements for ISO/IEC 27001:2022. Certification bodies had to complete every client transition by that deadline.
Stale documents circulate for ordinary reasons. A 2013 certificate sitting on a supplier’s website is usually a page nobody has updated, but the same document attached to a tender response is a live claim about current certification, and asking for the replacement before you score the submission is reasonable at any point in a procurement.
What changed in the 2022 version?
ISO/IEC 27001:2022 restructured the Annex A control set and added controls that did not appear in the 2013 edition, including one covering information security for the use of cloud services. A supplier last assessed under the 2013 edition was never examined against them. For anyone buying a hosted or cloud-delivered service, that is where the practical gap sits, because certification granted before the transition describes a security programme audited before those controls existed.
Scope decides whether an ISO 27001:2022 certificate reaches your contract
The scope statement draws the boundary of the management system that was audited. It can name one business unit, or a single named platform, with the rest of the organisation outside it. A supplier can hold entirely current certification for its internal IT function while the service in your specification runs somewhere no auditor has been.
Read the scope against your specification rather than against the supplier’s name. Where the requirement is secure hosting, the scope should name the platform and the sites it operates from. Where a subcontractor runs the infrastructure, ask whether that subcontractor sits inside the supplier’s scope or holds certification of its own. A scope covering a prime contractor’s offices leaves the data centre your citizens’ records will live in outside the audit.
This is also the check most often skipped, because the certificate looks correct. The date is current and the certification body is a name everybody recognises, and neither is disturbed by a scope statement that stops well short of the work.
Verify the certificate on UKAS CertCheck
Accredited certification in the UK is published and free to search on UKAS CertCheck. Enter the supplier and the record returns the standard, the certification body and the current status, which takes a claim in a bid document and turns it into something you can cite in an evaluation record.
Only UKAS-accredited certification appears there. Where the issuing body is accredited by another national accreditation body, that body’s register is the one to search. Whether the certifier holds accreditation at all is the check sitting behind this one, and we cover it alongside the other pre-award checks in security accreditations public sector suppliers need.
When a supplier sends a certificate that does not fit
Two failures recur in bid documents and each needs a different question. Where the certificate is out of date, ask for the current certificate number and the certification body, then check the record. If nothing resolves against ISO/IEC 27001:2022, ask when the supplier expects to complete assessment, and score the answer on what can be evidenced now rather than what is scheduled.
An out-of-scope certificate is the harder one, because the document is genuine and the supplier is not being evasive. Ask for written confirmation that the service being tendered sits inside the certified scope, and for the plan and date where it does not. That question converts a written claim into a commitment, and it costs nothing before shortlisting, where the same question after award costs a contract variation.
AxisTwelve is certified to ISO/IEC 27001:2022 through BSI, certificate number 598644, which a buyer can confirm on CertCheck. The rest of what we hold is listed on our certifications page.
Frequently asked questions
How do I check whether a supplier is ISO 27001 certified?
Two details make a certificate checkable: its number, and which body issued it. With both, search UKAS CertCheck, which is free and public. If the record does not resolve, the certification is not UKAS-accredited and the issuing body’s own register is the next place to look.
Does a supplier’s ISO 27001 certificate cover its subcontractors?
Only where the scope statement says so. Certification applies to the organisation and the activities named in the scope, so a subcontractor running your infrastructure sits outside it unless the scope names it. Ask for that subcontractor’s own certificate and check its scope the same way.
What should we ask for if a certificate does not name our service?
Ask the supplier to confirm in writing whether the service falls inside the certified scope, and if it does not, when the scope will be extended and by which certification body. Score the response on what can be evidenced now.